First published: Thu Oct 17 2024(Updated: )
The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.6.0 due to the insecure 'administrator' default value for the 'default_user_role' option. This makes it possible for unauthenticated attackers to register an administrator user even if the registration form is disabled.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Miniorange OTP Verification with Firebase WordPress | <=3.6.0 | |
UserPro | <=3.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9863 is classified as a high severity vulnerability due to its potential for privilege escalation.
To fix CVE-2024-9863, update the UserPro plugin for WordPress to version 3.6.1 or later.
CVE-2024-9863 affects users of the UserPro plugin for WordPress in versions up to and including 3.6.0.
Attackers can exploit CVE-2024-9863 to register as an administrator user without authentication.
Yes, a patch is available in version 3.6.1 of the UserPro plugin that addresses CVE-2024-9863.